Privacy Policy

1. Object and scope

We take the protection of your personal data very seriously. With this data privacy statement, we inform you about what personal data we collect, and how and for what purpose we process these data. We always handle your personal data in accordance with the statutory data protection regulations and this data privacy statement.

2. Controller

The controller in terms of the General Data Protection Regulation (GDPR), other data protection laws applicable in the member states of the European Union and other data protection provisions is:

Zentrum Digitalisierung.Bayern
Lichtenbergstr. 8
D-85748 Garching
Germany

Phone: +49 89- 248807 – 100
E-mail: info@zd-b.de

3. Data Protection Officer

Contact information for the Data Protection Officer:

Phone: +49 89 2488071 – 60
E-mail: datenschutzbeauftragter@zd-b.de

Any data subject may contact our Data Protection Officer directly with all questions and suggestions.

4. Visiting the website

Whenever our website is accessed, our system automatically records data and information about the accessing computer. The IP address of the device you are using has to be processed in order to display website pages in your browser, along with other information about the browser on your device.

According to data protection law, we are obliged to ensure the confidentiality and integrity of the personal data processed by our IT systems. The data are also used to eliminate website defects.

We record the following data for this purpose:

  • Browser type and version
  • Operating system used
  • Referrer URL (the previously visited page)
  • Host name of the accessing computer (IP address)
  • Time of the server request

These data are regularly erased after 7 days.

Our website is hosted by a service provider in the European Economic Area. A processing contract according to Art. 28 GDPR is in place.

The legal basis for data processing is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the operation of this website and the realisation of the protection goals of data confidentiality, integrity and availability.

5. Contacting and customer database

When you contact us to request information, the information provided by you is stored for the purpose of handling your enquiry. We require the information provided using the contact form on the website in order to handle your enquiry, address you correctly and provide you with a response.

The legal basis for data processing is point (f) of Art. 6(1) GDPR. Our overriding legitimate is communication with customers and prospects. When the object of making contact is to enter into a contract, the legal basis also includes point (b) of Art. 6(1) GDPR.

6. Registration for events

In the course of registering for an event and taking part in an event, we process your data provided during registration and collected in the course of taking part in the respective event for the purpose of registering and taking part in the event. Here the legal basis is point (b) of Art. 6(1) GDPR, that is the performance of the contract for taking part in the respective event and the pre-contractual measures that follow your enquiry. In the course of registering and participating in a qualification event, we send information to you by mail and/or e-mail using the contact data provided by you.

7. Cookies

Our website uses cookies. Cookies contain information transmitted by our web server or third-party web servers to your browser and stored there for future access. Cookies take the form of small files or other means of storing information. Information related to the respective specific device being used is stored in cookies. Cookies contain a distinguishing character string that permits the unique identification of the browser when the website is accessed again. A cookie also contains information about its origin and retention period. However, this does not mean we have direct knowledge of your identity as a result.

We use cookies to make our website more user friendly.

For one, we use what are known as session cookies that are only stored for the duration of the respective visit to our website (for example to store the contents of your shopping cart). A session cookie contains a randomly generated, unique identification number called a session ID. Session cookies are automatically erased after leaving our website. We also use temporary cookies stored by us on your device for a certain period of time (known as first-party cookies). When you visit our website again, we automatically recognise that you have visited us before and what your input and settings were, so you do not have to repeat these.

We also use cookies for other purposes such as web analytics, conversion tracking and re-marketing. These cookies are automatically erased after a respective defined time period as well. Their use is explained in more detail below.

You can prevent the placement of cookies by configuring your browser settings accordingly. However, please be advised that this may limit the use of our website. Cookies do not install or start any programs or other applications on your computer.

You can object to the use of cookies for the purpose of measuring coverage and for promotional purposes on the deactivation page of the network advertising initiative (http://optout.networkadvertising.org/) and on the US website  (http://www.aboutads.info/choices) or the European website (http://www.youronlinechoices.com/uk/your-ad-choices/).

The legal basis for processing personal data through the use of cookies is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the operation, analysis and optimisation of our website and our customer interactions.

8. Web analytics

We use web analytics services on our website or parts thereof in order to record how visitors use our website and to optimise the website as a whole and its presentation.

We use the web analytics service Matomo from the service provider InnoCraft Ltd. in New Zealand. Data about the use of our website by its users are collected in the course of using Matomo. These data are stored on our server and not transmitted to Matomo. The collected IP addresses of visitors to our website are anonymised prior to storage. No cookies are set in the course of using Matomo.

The legal basis for data processing when using web analytics is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the analysis, optimisation and economical operation of our website and our customer interactions.

9. YouTube

There are embedded YouTube videos on our website. These are delivered using a plugin from YouTube, LLC in the USA (“YouTube”).

When you visit a website with the YouTube plugin, a connection to YouTube is unavoidably established and your IP address is transmitted to YouTube. If you are logged on to YouTube, the transmitted information can be linked to your account.

Further information about data protection by YouTube is found in YouTube’s data protection and security centre: https://support.google.com/youtube/topic/2803240?hl=de&ref_topic=6151248

YouTube as a Google group company is certified under the Privacy Shield agreement and thereby guarantees compliance with European data protection law: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.

The legal basis for data processing in the course of using YouTube is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the optimisation and economical operation of our website.

10. Google Maps

We use the Google Maps service (API) from Google LLC in the USA on our website. Google Maps permits the representation of interactive maps. When accessing pages on the website where Google Maps is used, information about your use of our website (such as your IP address) is transmitted to the Google servers in the USA where it is stored.

Personal data are transmitted to a third country outside the EU when using Google Maps. Google holds a Privacy Shield certificate that is available here: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.

Appropriate guarantees for data transmission are therefore in place according to Art. 46 GDPR.

Further information about data processing by Google is found in Google’s data protection information: https://www.google.com/policies/privacy.

The legal basis for data processing when using web analytics is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the analysis, optimisation and economical operation of our website and our customer interactions.

11. Social media buttons

Various social media buttons of the social media networks LinkedIn, Xing, Twitter, Facebook, Google+ and YouTube are integrated into our website, identified by their respective logos.

When you click one of these social media buttons, you are taken to our pages for the respective social media network. In this case, the provider of the respective social media network receives the information that your browser has accessed the corresponding page of our website, even if you do not have a profile for the respective social media network or are not logged on there. This information (including your IP address) is transmitted by your browser directly to a server of the respective provider. When you click a social media button and are either logged on to the respective social media network or then log on to the site of the respective social media network, the transmitted information can be assigned to your account for the social media network.

Please see the data protection information of the respective social media network provider for information about the purpose and scope of data collection and processing by the provider of the respective social media network, the identification of the provider, contact information and your rights and possible settings for the purpose of data protection.

The legal basis for the integration and use of social media buttons is point (f) of Art. 6(1) GDPR. Our overriding legitimate interest is the marketing of our offerings and our website.

12. Age restriction

This website is not intended or designed for use by children below the age of 16. We do not knowingly collect data from or about persons less than 16 years of age.

13. Data recipients

Within our organisation, your data are provided to the internal bodies and/or organisation units that require them for the fulfilment of their tasks, where applicable for the performance of contracts with you, for data processing with your consent or to protect our overriding legitimate interests.

Data are only disseminated to third parties within the framework of the applicable legal provisions. We only pass your data on to third parties when this is required for contractual purposes based on point (b) of Art. 6(1) GDPR or to protect our overriding legitimate interest in effectively conducting our business operations according to point (f) of Art. 6(1) GDPR.

To the extent we engage service providers and/or third-party providers in the course of delivering the website and/or our services, we take suitable legal precautions and implement corresponding technical and organisational measures to ensure the protection of your personal data.

To the extent we use content or tools of service providers and/or third-party providers whose registered office is in a third country in the course of delivering the website and/or our services, data are regularly transferred to a third country. A third country is any country where the GDPR does not constitute directly applicable law, that is any country outside the EU/EEA. The transmission of data to third countries takes place only if an adequate level of data protection is assured, with consent or with other legal authorisation, in particular a suitable guarantee according to Art. 46 GDPR.

14. Information about guaranteeing fair and transparent processing

14.1 Your rights

You have the right to obtain information free of charge about your stored personal data, their origins and recipient and the purpose of data processing, as well as the right to correction, deletion or blocking of these data. You also have the right to the restriction of processing and to object to processing.

Furthermore, you have the right to have your data that are subject to automated processing by us delivered to you or a third party in a common machine-readable format. To assert your rights, please contact us using the contact information provided above for the controller.

You also have a right to complain to the responsible supervisory authority for data protection. The supervisory authority responsible for data protection law matters is the Bavarian State Office for Data Protection Supervision (https://www.lda.bayern.de/).

Many data processing procedures are only possible with your express consent. You may withdraw your existing consent at any time. An informal e-mail message to us is sufficient. The lawfulness of data processing prior to the withdrawal of consent remains unaffected.

Insofar as we process your data for the protection of our overriding legitimate interests as explained in this data privacy statement, you may object to this processing with future effect. To do so, please contact us using the contact information provided for the controller.

In principle you only have this right to object on grounds relating to your particular situation (Art. 21(1) GDPR). After exercising your right to object, we shall no longer process your personal data for these purposes unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or in case of processing for the establishment, exercise or defence of legal claims.

In case of processing for direct marketing purposes, you may exercise your corresponding right to object at any time (Art. 21(2) GDPR) and we shall then discontinue the processing of your personal data for direct marketing purposes regardless of the reasons for your objection.

14.2 Mandatory disclosures

Providing personal data is not required by law or contract. You are not obliged to provide personal data. However, providing personal information is required to enter into a contract insofar as certain information is indispensable in order to conclude a contract.

14.3 Automated decision making

We do not perform automated decision making including profiling.

15. Storage and erasure

We adhere to the principles of data avoidance and data economy. Therefore, we only store your personal data for as long as required to achieve the purposes described here, or as required by retention periods imposed by lawmakers.

When the purpose of storage ceases to apply or the retention period prescribed by the lawmaker ends, personal data are routinely erased or blocked in accordance with the applicable legal regulations.

16. Technical and organisational data security measures

We implement organisational, contractual and technical security measures according to the state of the art in order to ensure compliance with data protection law regulations and to protect the data processed by us against accidental or intentional manipulation, loss, destruction or unauthorised access.

Our website uses SSL encryption for security reasons and to protect the transmission of confidential content such as orders, enquiries or payment data you send to us.

17. Amendment of this data privacy statement

We reserve the right to amend this data privacy statement on occasion in order to consistently comply with the applicable current legal requirements or to implement changes to our offering in the data privacy statement, for example when we introduce new services. In this case, the new data privacy statement applies for your subsequent visits.